Free version 1.0.0 is available from the official WordPress.org Plugin Directory. Premium plans and downloads are available from the pricing page.
Configure
- Create a Turnstile widget in the merchant's Cloudflare account
- Add the checkout hostnames to that widget
- Choose Cloudflare Turnstile in Settings and enter the site and secret keys
- Save and use the built-in verification action before relying on it
Data boundary
The widget loads only on a challenged checkout. Server verification sends the response token and merchant secret to Cloudflare, omits the optional shopper IP, and sends no payment details. Turnstile can be used without placing the entire site behind Cloudflare.
Related resources
How the decision flow works · Compatibility matrix · Support · Public source